Aesto Health Data Breach Exposes Records of Over 9.5 Million Patients
Healthcare technology provider **Aesto Health** has disclosed a significant data breach, impacting over 9.5 million individuals. The incident, which compromised patient data stored in their **Amazon Web Services** infrastructure, highlights ongoing vulnerabilities in the health tech sector.

**Aesto LLC**, operating as **Aesto Health**, a private technology company specializing in software-as-a-service solutions for healthcare organizations, recently announced a data breach affecting more than 9.5 million individuals.
### Incident Details and Timeline
The company initially informed the public on June 24 via a website notification, confirming a compromise of a "limited portion" of its **Amazon Web Services** (AWS) infrastructure. However, the intrusion itself occurred between December 2, 2025, and December 18, 2025. Internal confirmation of the breach followed an extensive forensic investigation by external specialists, concluding on May 26, 2026.
**Aesto Health**'s official statement clarifies: "After an extensive forensic investigation and manual document review, on May 26, 2026, we confirmed that between on or about December 2, 2025, and December 18, 2025, certain protected health information belonging to patients of various Covered Entity clients stored within Aestoβs network may have been accessed and/or acquired by an unauthorized actor."
### Scope of Compromised Data
In a report submitted to the **U.S. Department of Health and Human Services**, **Aesto Health** confirmed that the breach impacted 9,540,683 individuals. The compromised information is extensive and highly sensitive, including:
* Full names
* Dates of birth
* Medical information
* Driverβs license numbers
* Financial account numbers
* Health insurance information
* Individual taxpayer identification numbers
* Other government identification numbers
* Social Security numbers
### Impacted Healthcare Providers
The **HIPAA Journal** reported that this incident indirectly affects 29 healthcare providers. Notable entities among them include **VillageMD**, **Everside Health** (**Marathon Health**), **Marana Health**, and **Together Womenβs Health**.
### Remediation and Notifications
Starting August 21, **Aesto Health** began notifying affected individuals, providing details about the incident and instructions to enroll in a 24-month identity theft protection and credit monitoring service through **Experian**. This aims to mitigate potential fallout from the exposure of such critical personal data.
### A Growing Trend in Health Tech Breaches
This incident is part of a disconcerting trend of data breaches targeting health technology software companies. Recent examples include breaches at **iRhythm**, **Xolis**, **Medronic**, **MCBS**, **Health-ISAC**, **Unlimited Technology Systems**, **CareCloud**, **Nutex Health**, and **McKesson**. The frequency and scale of these attacks underscore the critical need for robust cybersecurity measures within the healthcare sector, especially for third-party service providers handling vast amounts of sensitive patient data.
As of the time of writing, no specific threat groups have publicly claimed responsibility for the **Aesto Health** attack.